The DPDP Act is Sub Judice, But the Compliance Clock is Ticking: Why the SC’s Refusal to Stay Changes Everything for Data Fiduciaries
The Constitutional Dark Cloud Over the DPDP Act In the legal corridors of New Delhi, a dangerous game of 'wait and see' is playing out. Following the Supreme Court’s decision in early 2026 to refer challenges against the Digital Personal Data Protect...
The Constitutional Dark Cloud Over the DPDP Act
In the legal corridors of New Delhi, a dangerous game of 'wait and see' is playing out. Following the Supreme Court’s decision in early 2026 to refer challenges against the Digital Personal Data Protection (DPDP) Act, 2023 and its 2025 Rules to a larger bench, a sizable chunk of the corporate bar seems to have hit the snooze button on compliance. This is a fatal miscalculation.
Yes, the Supreme Court issued notice on writ petitions challenging the fundamental validity of the Act. Yes, the April 2026 petitions rightly attack Section 44(3) of the DPDP Act for effectively neutering the Right to Information (RTI) Act, 2005. But the most critical takeaway for practicing lawyers from these hearings wasn't the referral to a larger bench—it was the Supreme Court’s unequivocal refusal to stay the operation of the DPDP Act.
For data and technology lawyers, the mandate is clear: the legislation has shifted from a theoretical debate to an enforcement-ready compliance regime. The Data Protection Board (DPB) is not going to wait for a Constitution Bench to determine the fate of India's privacy framework before knocking on your client's door.
Privacy vs. Transparency: The Section 44(3) Dilemma
To understand why the DPDP Act is facing constitutional headwinds, we must look at the blatant friction between data privacy and public transparency. The core of the current Supreme Court challenge revolves around Section 44(3) of the DPDP Act.
Before the DPDP Act, Section 8(1)(j) of the RTI Act provided a nuanced balancing test. It exempted personal information from disclosure unless the Central Public Information Officer (CPIO) was satisfied that the larger public interest justified the disclosure. It was a statutory embodiment of proportionality.
Enter Section 44(3) of the DPDP Act, which bulldozes this nuance. It amends Section 8(1)(j) to create a blanket exemption for all personal information, stripping the CPIO of the power to apply the public interest override. The April 2026 petitions correctly argue that this creates an opaque administrative state, masking vital data under the guise of privacy.
"While KS Puttaswamy elevated privacy to a fundamental right, it never intended for privacy to be weaponized as a shield against the fundamental right to information under Article 19(1)(a). A blanket ban on disclosing personal information under the RTI Act fails the proportionality test."
However, while constitutional lawyers battle over the ghost of Puttaswamy and the sanctity of the RTI Act, corporate counsel must pivot to a harsher reality: the DPDP Rules 2025 are live, and the operational timelines are closing in.
The Operational Reality: Consent Governance is the New Battleground
If you are advising Data Fiduciaries (the DPDP equivalent of data controllers), the RTI dispute is academic. Your immediate nightmare is Section 6 of the DPDP Act—the consent provision.
Legal commentary throughout early 2026 has consistently pointed to one glaring issue: Indian companies are woefully unprepared to overhaul their consent architectures. Under the DPDP framework, consent must be free, specific, informed, unconditional, and unambiguous.
What does this mean for your practice?
- The Death of Bundled Consent: You can no longer bury a data processing clause deep within a 50-page Terms of Service document. "By clicking accept, you agree to our privacy policy" is now legally dead. If a client is collecting data for delivery, they cannot make consent for marketing analytics a condition for the service.
- Notice Requirements (Section 5): The Notice must be itemized. It must explicitly state what data is collected and for what purpose, available in English and all 22 languages in the Eighth Schedule. If your client hasn't started localizing their privacy notices, they are already behind.
- The Withdrawal Friction Trap: The law dictates that withdrawing consent must be as easy as giving it. If an application allows users to grant consent via a single UI toggle, but forces them to send an email to a Grievance Officer to withdraw it, that Data Fiduciary is in breach.
Taking a Position: Stop Stalling, Start Mapping
The prevailing sentiment among some in-house teams that "the law might change, so let's wait" is negligent. Even if the Supreme Court eventually strikes down or reads down Section 44(3) to restore the RTI Act's public interest test, the core obligations placed upon private Data Fiduciaries—data minimization, breach disclosure, and consent management—will remain untouched.
Practicing lawyers need to shift their clients from a state of legislative paralysis to operational readiness. This involves:
- Conducting Data Discovery: You cannot protect (or delete) what you don't know you have. Data mapping is the immediate priority.
- Reviewing Legacy Data: Section 5(2) requires Data Fiduciaries to send a fresh notice to all individuals whose personal data was collected before the Act's commencement. Drafting this retroactive notice strategy will be a massive logistical undertaking.
- Renegotiating Data Processor Agreements: Under the DPDP Act, the Data Fiduciary is strictly liable for the breaches of its Data Processors. Indemnity clauses in vendor contracts need immediate, aggressive redrafting to shift financial liability downstream.
The Supreme Court will take its time dissecting the constitutional minutiae of the RTI amendments. But the Data Protection Board will not wait. The era of data free-for-alls in India is over. It is time for lawyers to advise their clients to build the compliance infrastructure today, or prepare for crippling penalties tomorrow.
Tags
Published by AnrakLegal AI